Back to the Journal
ZF PRIVACY-01ZFINANCE RESERVEPrivacy Policy
zFinance Journal

Privacy Policy

Last updated: July 2026 — Version 1.0 (Journal / blog only)
Scope: This Privacy Policy covers only the zFinance Journal — the blog you are reading now. The marketing website zfinanceapp.com and the zFinance mobile application each have their own separate privacy policies, and nothing here describes processing that happens there.

1. Who we are (Controller)

The controller for personal data processed on this blog — within the meaning of Art. 4(7) GDPR, data controller under the Turkish Personal Data Protection Law (KVKK, Law No. 6698), and "business" under the California Consumer Privacy Act (CCPA/CPRA) — is:

Bonita İnternet Teknoloji Ticaret Ltd.
General Manager: Sefa Koç
Company No: 789758-0
Altunizade Mah. Ord. Prof. Fahrettin Kerim Gökay Cad. No: 35/1
Üsküdar / Istanbul, Türkiye
General contact: info@zfinanceapp.com

Person responsible for data protection: Bera Duranoğlu
Privacy contact: privacy@zfinanceapp.com

Please use the privacy address for any data-protection request (access, deletion, objection, complaint). We aim to respond within statutory deadlines — typically 30 days under GDPR/KVKK, 45 days under CCPA.

2. What this blog is

The Journal is an editorial record of what we do at zFinance: events we attend, products we launch, people we work with, and occasional looks behind the scenes. It is a publication, not a product. You can read every article without an account, without logging in, and without giving us any information at all.

3. What we collect

3.1 Automatically, when you load a page. Our host receives the technical data your browser sends in order to deliver the page:

  • your IP address;
  • date, time and time zone of the request;
  • the page or file requested;
  • HTTP status code and volume of data transferred;
  • the referring URL, if any;
  • your browser type, version and user-agent string;
  • your operating system and device type.

This lands in short-lived server logs. We do not use it to identify you, build a profile, or combine it with anything else.

3.2 If you subscribe to the newsletter. We collect your email address, the time you submitted the form, and the IP address you submitted it from (used by Mailchimp for double-opt-in and anti-abuse). We ask for nothing else.

3.3 If you email us. We receive your address, any name you give, and the content of your message — used solely to reply.

3.4 Web fonts. This blog loads its typefaces from Google Fonts. Your browser therefore requests files from fonts.googleapis.com and fonts.gstatic.com, and in doing so transmits your IP address to Google. See Section 5.3.

3.5 Sensitive data. We do not knowingly collect special categories of data (Art. 9 GDPR / KVKK Art. 6, or sensitive personal information under CPRA). Please do not send us any.

What we do not collect. This blog sets no cookies. It runs no analytics — no Google Analytics, no Tag Manager, no pixels, no session replay, no heatmaps. It stores nothing on your device — no localStorage, no sessionStorage. There is no cookie banner because there is nothing to consent to. We do not know how many of you there are, which articles you read, or how far you scroll.

4. Why we process it, and on what legal basis

(a) Delivering and securing the blog — technical access data (3.1).
GDPR Art. 6(1)(f) — our legitimate interest in a stable, secure publication. KVKK Art. 5(2)(f). CCPA: security, integrity and debugging.

(b) Sending the newsletter — your email address (3.2).
GDPR Art. 6(1)(a) — your consent, given by submitting the form. You may withdraw it at any time via the unsubscribe link in every email. KVKK Art. 5(1) — explicit consent (açık rıza), including under the Turkish Law on Electronic Commerce (No. 6563). CCPA: collected directly from you with notice; opt out at any time.

(c) Replying to your emails — GDPR Art. 6(1)(b) or 6(1)(f); KVKK Art. 5(2)(c)/(f).

(d) Displaying the blog's typography — GDPR Art. 6(1)(f), our legitimate interest in consistent presentation (3.4, 5.3).

(e) Publishing editorial content, which may name or depict people — see Section 10.
GDPR Art. 6(1)(f) together with Art. 85 (processing for journalistic purposes and freedom of expression). KVKK Art. 5(2)(f) and Art. 28.

(f) Legal obligations and legal claims — GDPR Art. 6(1)(c) and 6(1)(f); KVKK Art. 5(2)(a) and 5(2)(e).

5. Service providers

5.1 Hosting — Netlify, Inc.
44 Montgomery Street, Suite 300, San Francisco, CA 94104, USA
Role: static hosting and content delivery for this blog.
Processing: global CDN; some processing may take place in the United States.
Safeguards: EU Standard Contractual Clauses under Art. 46(2)(c) GDPR; Netlify participates in the EU-U.S. Data Privacy Framework.
Privacy: netlify.com/privacy

5.2 Newsletter — Mailchimp (Intuit Inc.)
2700 Coast Avenue, Mountain View, CA 94043, USA
Role: storing the subscriber list, sending the newsletter, managing opt-in and opt-out.
Processing: United States, with global delivery infrastructure.
Safeguards: EU Standard Contractual Clauses; Intuit/Mailchimp participates in the EU-U.S. Data Privacy Framework; for Türkiye, explicit consent at the point of submission.
Privacy: intuit.com/privacy/statement

5.3 Web fonts — Google Ireland Ltd. / Google LLC
Gordon House, Barrow Street, Dublin 4, Ireland (EU/EEA) / 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Role: delivering the typefaces used on this blog (Fredoka, Inter, JetBrains Mono) from Google's font CDN.
Data: your IP address, user-agent and the referring page are transmitted to Google when the fonts load. Google states that font requests do not set cookies.
Safeguards: EU Standard Contractual Clauses; Google participates in the EU-U.S. Data Privacy Framework.
Privacy: policies.google.com/privacy

These three are the only third parties involved in this blog. We use no analytics provider, no advertising network, and no behavioural-analytics tool.

6. Cookies and local storage

This blog uses no cookies and no browser storage of any kind — neither strictly necessary nor analytical. We set no identifiers, and we do not read any. Consequently there is no consent banner and no preference centre: there is nothing to accept or decline.

If you subscribe to the newsletter, Mailchimp may set cookies on its own pages (for example the confirmation page you reach after clicking the link in the confirmation email). Those are governed by Mailchimp's privacy policy, not this one.

7. International transfers

Because our host (Netlify), our newsletter provider (Mailchimp) and our font provider (Google) rely in part on infrastructure in the United States, some processing takes place outside the EU/EEA and Türkiye. For these transfers we rely on:

  • EU Standard Contractual Clauses under Art. 46(2)(c) GDPR (Commission Implementing Decision (EU) 2021/914);
  • the recipient's participation in the EU-U.S. Data Privacy Framework;
  • for data originating in Türkiye, your explicit consent (açık rıza) under KVKK Art. 9 where applicable.

You can request a copy of the relevant safeguards at privacy@zfinanceapp.com.

8. Who receives your data

We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA/CPRA. We have not done so and have no plans to. Data is disclosed only to:

  • the providers in Section 5, acting as processors under contract;
  • public authorities, where legally compelled;
  • professional advisors bound by confidentiality, where strictly necessary;
  • a successor in the event of a merger or acquisition — in which case you will be notified and your rights preserved.

9. How long we keep it

  • Server logs — deleted or anonymised within 7 days, unless needed longer to investigate a security incident.
  • Newsletter address — kept until you unsubscribe or ask us to delete it, then removed from active systems within 30 days. Backups are overwritten on rolling cycles.
  • Email correspondence — kept for the duration of the matter and up to 12 months after, unless statutory retention applies.
  • Published articles — remain online indefinitely as an editorial archive, subject to Section 10.
  • Statutory retention — where applicable, Turkish Tax Procedure Law and German commercial and tax law (§§ 257 HGB, 147 AO) require retention for up to 10 years.

10. People and photographs in our articles

This is a blog about events and the people we meet at them. Articles may therefore contain names, quotes, and photographs of identifiable individuals — colleagues, partners, speakers, attendees.

We publish such content on the basis of our legitimate interest in reporting on our own activities (GDPR Art. 6(1)(f)), read together with Art. 85 GDPR, which requires member states to reconcile data protection with freedom of expression and information. Where a photograph is taken at a private gathering rather than a public event, we rely on the consent of the people shown.

If you appear in an article and would rather not: write to privacy@zfinanceapp.com and tell us which article and which image or passage. We will review it promptly and, in the ordinary case, remove or blur it — we would much rather take a photo down than argue about it. You also have the right to object under Art. 21 GDPR and the rights in Section 11.

Please do not send us photographs of other people for publication unless you have their agreement.

11. Your rights

11.1 EU, EEA, UK and Switzerland (GDPR / UK GDPR). You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection to processing based on legitimate interest (Art. 21), withdrawal of consent at any time without affecting prior lawfulness (Art. 7(3)), and complaint to a supervisory authority (Art. 77). We carry out no automated decision-making within the meaning of Art. 22 on this blog.

11.2 Türkiye (KVKK Art. 11). You have the right to learn whether your data is processed; to request information if it has been; to learn the purpose and whether it is used accordingly; to know the third parties to whom it has been transferred at home or abroad; to request correction, erasure or destruction under Art. 7; to request that these operations be notified to third parties; to object to results produced solely by automated analysis; and to claim compensation for damage caused by unlawful processing. You may complain to the Turkish Personal Data Protection Authority (kvkk.gov.tr).

11.3 California (CCPA/CPRA). You have the right to know and access the categories and specific pieces of personal information collected, their sources, the purpose, and the categories of third parties involved; to delete; to correct; to opt out of "sale" or "sharing" (as noted, we do neither); to limit use of sensitive personal information (we do not knowingly collect any); and to non-discrimination for exercising these rights. You may use an authorised agent. We may need to verify your identity first.

11.4 Elsewhere. We will honour reasonable requests for access, correction or deletion even where no specific law compels us to.

To exercise any of these: email privacy@zfinanceapp.com with enough detail for us to identify you and your request.

12. Supervisory authorities

  • EU/EEA — the authority of your country of residence, place of work, or place of the alleged infringement.
  • Germany — the Landesdatenschutzbeauftragter of your federal state.
  • UK — Information Commissioner's Office (ico.org.uk).
  • Türkiye — Kişisel Verileri Koruma Kurumu (kvkk.gov.tr).
  • California — California Privacy Protection Agency (cppa.ca.gov) and the Attorney General.

13. Security

The blog is served over TLS/HTTPS. It is a static site: there is no database, no login, and no user-generated input beyond the newsletter field, which reduces the attack surface considerably. Access to the subscriber list is restricted on a need-to-know basis, and we review our providers before using them.

No transmission over the internet is ever completely secure. If a personal-data breach occurs that is likely to result in a high risk to your rights, we will notify you and the competent authority within the statutory deadline (72 hours under Art. 33 GDPR).

14. Children

This blog is not directed at children under 13 (or under 16 where applicable) and we do not knowingly collect their data. If you believe a child has given us personal data, write to privacy@zfinanceapp.com and we will delete it promptly.

15. Links to other sites

Articles and the footer link to other websites, including zfinanceapp.com. We are not responsible for their privacy practices. Please read their policies before giving them your data.

16. Changes to this Policy

We may update this Policy. The current version always lives on this page with the date below. If we make a material change, we will say so on the blog or tell you directly where the law requires it.

17. Contact

Bera Duranoğlu — responsible for data protection
Bonita İnternet Teknoloji Ticaret Ltd.
Altunizade Mah. Ord. Prof. Fahrettin Kerim Gökay Cad. No: 35/1, Üsküdar / Istanbul, Türkiye
Privacy: privacy@zfinanceapp.com
Everything else: info@zfinanceapp.com